Slashdot Mirror


Users Report Foul Play In App Store Rankings, Purchases

An anonymous reader writes "Two iPhone App developers have spotted what appears to be a hacking of the App store rankings by a rogue developer. The rankings in the books category of the US iTunes store features 40 out of 50 apps by the same app developer, Thuat Nguyen. What's more concerning is that it seems individuals' iTunes accounts have been hacked to make mass purchases of that one developer's apps." Among the comments attached to the linked story is one which suggests the security problem may lie elsewhere.

6 of 144 comments (clear)

  1. Re:Hrm by socceroos · · Score: 5, Insightful

    Meh, every online store is going to have its weaknesses. Unfortunately, most of the time, the greatest weakness is the users themselves.

    Not trying to justify iTunes - I hate it. Just saying that I doubt its any more 'hackable' than the next online store.

  2. Fowl Play by brianwells · · Score: 5, Funny

    The only fowl play I've found so far is Angry Birds.

  3. Possible details from AppleInsider by immaterial · · Score: 5, Informative

    Last month, a user posted a forum comment stating, "I am going to tell you the truth about what has been going on with your account." The anonymous user then explained, "let’s say you are a Chinese guy or girl with an iPhone or iPad and you want to get some music, movie or app. How you do you do it? You go to http://www.taobao.com/ The (by far) largest online market in the world and type iTunes in the search bar. Immediately you will be presented with a list of more than 7,000 items.

    "You want to save money, so you filter the list to show only items under RMB25.00- (US $3.60) and still you have more than 3,600 offers. So you pick some one at random like, as an example, this one: http://item.taobao.com/item.htm?id=5516054242. You open the online chat and you transfer him RMB22.00 (US $3.20). He ask you in the online chat to provide a new iTunes account name and password, and you comply: User: qiuwge3foe3333@yahoo.com Password: qwer34567

    "He asks you to wait 10 minutes online. He has already a number of user accounts under surveillance, so he enters in the iTunes account of his victim, change his/her username and password to the one you provided, and come back to ask you try it and approve the transaction so Taobao.com releases his money. Even if you cant read Chinese you can see very clearly in his item description that this account will not last more than 24 hours (the time for his victim to see the charges mounting and then cancel the credit card).

    "He claims that he selects 'his' accounts so you can drain at least US $250.00 from them before they get cancelled. He urges you to be fast and buy and download as fast as you can. Start immediately! Keep the download going on for the full 24 hours! There is no warranties on how long it will last! Because he already changed the username and password, the victim can’t stop you.

    More details here though so far there's no explanation of how the accounts are getting hacked.

  4. Re:Hrm by Anonymous Coward · · Score: 5, Insightful

    Not liking assholes and viewing greed as a negative human quality doesn't necessarily make one a communist.

  5. Re:Hrm by Mitsoid · · Score: 5, Informative

    Other problem with iTunes,
    "All sales are final."

    From Terms and conditions, security section:
    "You are entirely responsible for all activities that occur on or through your Account, and you agree to immediately notify Apple of any unauthorized use of your Account or any other breach of security. Apple shall not be responsible for any losses arising out of the unauthorized use of your Account. "

    So better hope something else protects those people harmed, as I don't think California law (The "fall back" for iTunes T&C) will help much if a hacker steals $100-300 from you from another country.

    Glad I stopped storing my CC info with iTunes after they pulled products I paid for from the store and wouldn't let me re-download. They may have nice hardware, but their policies are horrible for end-users.

  6. Re:Use temporary credit card numbers online by noidentity · · Score: 5, Informative

    BTW, Slashdot has an automatic signature feature, which gives you two benefits: you don't have to add it manually after each post, and those readers who aren't interested in the clutter of signtures can turn them off. When you add it manually, you annoy the latter group.